GHSA-4wrr-9h5r-m92w
Dashboard / Vulnerabilities / GHSA-4wrr-9h5r-m92w
Summary: Apache Struts Remote Java Code Execution
Details: The `ExceptionDelegator` component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2012-0391, https://github.com/apache/struts/commit/25e50069d60434a30395e3a98357ffba2bed427e, https://github.com/apache/struts/commit/5f54b8d087f5125d96838aafa5f64c2190e6885b, https://github.com/apache/struts/commit/b4265d369dc29d57a9f2846a85b26598e83f3892, https://github.com/apache/struts, https://issues.apache.org/jira/browse/WW-3668, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0391, https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt, http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html, http://secunia.com/advisories/47393, http://struts.apache.org/2.x/docs/s2-008.html, http://struts.apache.org/2.x/docs/version-notes-2311.html, http://www.exploit-db.com/exploits/18329
Affected packages
Package
Name: org.apache.struts:struts2-core
Purl: pkg:maven/org.apache.struts/struts2-core
Affected ranges
Type: ECOSYSTEM
Events:
